harvard-art-museum-etl-pipeline

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The ETL/API/database behavior is coherent with the stated purpose, and credential/data flows are proportionate and direct to official endpoints. The main concern is install trust: the skill published by ara.so instructs cloning and executing code from an unrelated personal GitHub repository, plus unpinned Python dependencies, which creates meaningful supply-chain risk even without clear malicious behavior.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Oct 1, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fdata-skills%2Fharvard-art-museum-etl-pipeline%2F@af7336808d2423c58783627fa4951332ee35e03aae91646f0080d02f4f20519b
Security Audit — socket — harvard-art-museum-etl-pipeline